← BACK TO FEED
data breachfinancial servicescloud securityidentity theftHeights Finance

Heights Finance Breach Exposes Data of 1.2 Million Borrowers

Consumer lender Heights Finance Holdings suffered a data breach in early May when hackers accessed a third-party cloud-based storage platform, compromising the personal and financial information of over 1.2 million individuals. Stolen data includes names, Social Security numbers, bank account details, and other sensitive information belonging to current and former borrowers. Heights has secured the platform, notified federal law enforcement, and is offering affected individuals 24 months of free credit monitoring and identity protection services.

Consumer lender Heights Finance Holdings has begun notifying more than 1.2 million people that their personal and financial data was lifted by hackers who got into a third-party cloud storage platform the company used for customer records.

The breach was discovered in early May. Heights says its core loan management systems were untouched, which is the sort of silver lining companies always mention while glossing over the fact that enormous amounts of sensitive customer data walked out the door anyway.

The haul was comprehensive. Names, addresses, email addresses, phone numbers, Social Security numbers, government IDs, driver's licence numbers, bank account details, dates of birth. Essentially everything a fraudster needs to have a very productive few months at someone else's expense.

The scope is wider than just current Heights customers. Former borrowers of Curo Management and its associated brands are also potentially affected, as are people who simply enquired about or applied for a loan product, including through third parties. You don't even need to have been a Heights customer to find yourself in this.

State attorney general filings put the affected numbers at 734,828 in Texas and 486,463 in South Carolina, with handfuls of individuals in New Hampshire and Vermont rounding out the total past 1.2 million.

Heights is offering the standard post-breach consolation prize: 24 months of free credit monitoring and identity protection. The company says its dark web monitoring hasn't found the stolen data circulating yet, which is mildly reassuring but hardly a guarantee.

No ransomware or extortion group has publicly claimed responsibility, and Heights hasn't named any suspects. Outside cybersecurity specialists were brought in to investigate and the incident was reported to federal law enforcement, so the usual boxes have been ticked.

The third-party platform at the centre of this has since been secured, apparently. Cold comfort for the million-plus people now waiting to see whether their Social Security numbers turn up somewhere they shouldn't.

READ NEXT
EY Breach Exposes Client Tax Data Including SSNs and Card NumbersAccenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure KeysThreat Actor Claims Millions of Corporate Records Lifted from Azure Tenants